# IP INTELLIGENCE BRIEFING
Target: 119.73.115.115/32
Date: Analysis generated from IPDebrief intelligence platform
Classification: Moderate Risk (Score: 55/100)
---
## EXECUTIVE SUMMARY
IP address 119.73.115.115 presents a moderate risk profile with conflicting geolocation data and multiple blacklist listings. The IP is associated with AS138655 and shows recent threat activity signals. Current network services are firewalled with no open ports detected.
---
## TECHNICAL PROFILE
Risk Assessment
- Overall Risk Score: 55/100 (Moderate Risk)
- Operator Classification: Basic (Score: 0.2609)
- Route Stability: Unstable (isRouteStable: false)
- BGP Origin: AS138655 (119.73.115.0/24)
Geolocation Discrepancy
The IP exhibits conflicting geographic indicators:
- Primary Profile Data: US, New York (US-NY)
- Historical Observations: Pakistan, Islamabad (IS) via AS138655 trans world enterprise services
- Consensus: False (geoConsensus: false)
- GeoPlausible: False
Network Classification
- Infrastructure Type: Firewalled / No Services
- Service Types: Not cloud, CDN, VPN, proxy, Tor, hosting, mobile, or residential
- Open Ports: None detected
- DNS Resolution: static-host119-73-115-115.link.net.pk (net.pk domain)
---
## THREAT INDICATORS
Blacklist Status
- DNSBL Listings: 3 of 8 total lists
- Maximum Severity: High
- Listings Include: Multiple DNS blacklist entries (categories and severity levels vary)
Historical Signals (12 observations)
Recent activity from July 29, 2026 indicates:
- Threat indicators present (has_threats: true)
- Multiple DNS listings with high-severity classifications
- Pulse count: 1 (source: alienvault-otx)
Control Plane Data
- RPKI State: Not validated
- DNSSEC: Valid
- RR Route Changes (30d): 0
- Honeypot Strikes: 0
---
## NEIGHBORHOOD ANALYSIS
Subnet: 119.73.115.0/24
Total Neighbors: 48
Abuse Density: 0
Risk Distribution:
- High Risk: 0
- Medium Risk: 24
- Low Risk: 7
Notable Neighbors:
- 119.73.115.18: Risk Score 55, Authority Score 60
- 119.73.115.10: Risk Score 15, Authority Score 60
The subnet shows elevated medium-risk activity with no high-risk neighbors detected.
---
## RELATIONSHIP GRAPH
- DNS Associations: static-host119-73-115-115.link.net.pk (duplicate entries)
- No organization-level relationships identified
- No certificate matches
---
## RECOMMENDED ACTIONS
Immediate Recommendations
1. Monitoring: Increase logging verbosity and review recent activity from this IP (Severity: High)
Firewall Rules
iptables:
```
iptables -A INPUT -s 119.73.115.115 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 119.73.115.115 drop
```
nginx:
```
deny 119.73.115.115;
```
pfSense:
```
119.73.115.115/32
```
Cloudflare WAF:
```json
{
"description": "Block 119.73.115.115 β IPDebrief risk score 55",
"action": "block",
"filter": {
"expression": "ip.src eq 119.73.115.115"
}
}
```
AWS WAF:
```json
{
"Addresses": ["119.73.115.115/32"],
"Description": "IPDebrief risk 55"
}
```
---
## ANALYST NOTES
The geolocation discrepancy between US profile data and Pakistan historical observations warrants investigation. The high-severity DNSBL listings combined with the unstable routing status suggest this IP may be used for transient malicious activities. No active services are currently exposed, but the subnet's 24 medium-risk neighbors indicate potential related infrastructure.
Priority: Monitor and consider blocking based on organizational threat tolerance levels.
---
*This briefing is based on IPDebrief intelligence data. All recommendations are probabilistic and should be validated against additional threat intelligence sources before implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | TEC-DATA CORE ENGINEERING TEAM |
| ASN | AS138655 |
| Network Name | Naqashband |
| CIDR Block | 119.73.112.0/20 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | static-host119-73-115-115.link.net.pk |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | static-host119-73-115-115.link.net.pk |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 08:17:54 UTC |
| Last Seen | 2026-07-29 22:03:01 UTC |
| Profile Built | 2026-07-29 22:10:16 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.